Incident library.
Public incidents and studies, newest first. Each page says what its source reports, why it tends to happen, and how to check your own app in five minutes.
- June 2, 2026Study: 1,072 Supabase-backed apps built with AI tools scannedStudy · Symbiotic Security
- April 27, 2026Lovable: chat histories of public projects readableIncident · Halborn
- July 26, 2025Tea app: 72,000 user images exposedIncident · TechCrunch
- July 18, 2025Replit agent deletes a production database despite instructionsIncident · The Register
- May 29, 2025CVE-2025-48757: Lovable apps with readable Supabase tablesIncident · Superblocks
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
How it works, in four steps.
1 · Scan
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →